🔐 CVE Alert

CVE-2026-101283

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22

CWE CWE-122
Vendor esnet
Product iperf3
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for esnet iperf3

Be the first to know when new unknown vulnerabilities affecting esnet iperf3 are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

esnet / iperf3
3.20 3.21

References

NVD ↗ CVE.org ↗ EPSS Data ↗
newreleases.io: https://newreleases.io/project/github/esnet/iperf/release/3.22

Credits

Anthropic Ada Logics